Centralized Identity and Group-Based Policy
SafeSquid integrates with directory services to provide centralized user authentication and group-based access control. This ensures that web access policies are tied to enterprise identities and group memberships.Problem statement
IP-based proxy control is not enough for enterprise governance. Administrators need directory-backed user and group identity so policy, reporting, and investigations reflect the real actor behind the request.Supported Directory Services
Confirmed directory-related product capabilities today:
- Active Directory
- LDAP
- Kerberos
- SAML
- RADIUS
Why use Directory Services?
- Centralized Management: Manage users and groups in one place (AD/LDAP) instead of locally in SafeSquid.
- Group-Based Policies: Apply different access rules automatically based on directory group membership (e.g., Finance, IT, Sales).
- Single Sign-On (SSO): (Active Directory only) Authenticate users transparently using Kerberos tickets without browser prompts.
- Granular Audit: Access logs show exactly which directory user accessed which resource, simplifying compliance reporting.
Operational requirements
- Reliable DNS and NTP are required for stable directory-backed authentication.
- Kerberos is the documented transparent path for Active Directory environments.
- If transparent authentication is not viable, use prompt-based authentication and keep the user-experience trade-off explicit.
Choose your integration method
Active Directory (AD)
Best for Windows-centric environments. Supports SSO Authentication for the best user experience and Simple Authentication for non-domain devices or specific use cases.OpenLDAP
Best for Linux/Unix-heavy environments or organizations using OpenLDAP for identity. Supports Simple Authentication (LDAP bind) to validate credentials against the directory.Verification and validation
After integration, confirm:- users and groups are visible in the SafeSquid directory view
- authentication succeeds with a known test account
- group-based policies differentiate users as expected
- logs and reports show directory-backed identity instead of anonymous IP-only attribution
Source register
Next steps
- Choose your directory service above.
- Follow the Setup Integration guide to link SafeSquid with your directory.
- Configure Simple or SSO authentication rules.
- Combine with Access Restriction to enforce policies by directory group.

